feat: turn on sudo and admin prompts by default

This commit is contained in:
Felitendo committed 2026-09-28 14:39:31 +02:00
1 parent d8bbefed8a
commit c1cf6cd948
20 files changed
+487 -474

No files matched your search

+7 -3
View File
@@ -107,9 +107,13 @@ fu_do_enable() {
fu_note "$(fu_msg "No systemd user session, so the lock screen agent was not started.")"
fi
# What was on the last time face unlock was on.
[[ $CFG_SUDO == yes ]] && ! fu_pam_enabled sudo && fu_root pam-enable sudo
[[ $CFG_POLKIT == yes ]] && ! fu_pam_enabled polkit-1 && fu_root pam-enable polkit-1
# sudo and admin prompts: on unless turned off in the settings.
if [[ $CFG_SUDO == yes ]] && fu_pam_available sudo && ! fu_pam_enabled sudo; then
fu_root pam-enable sudo
fi
if [[ $CFG_POLKIT == yes ]] && fu_pam_available polkit-1 && ! fu_pam_enabled polkit-1; then
fu_root pam-enable polkit-1
fi
# The lock screens of Hyprland, Niri and the like only open themselves:
# the face goes into their password check. On unless turned off.
if fu_pam_lockers_here && [[ $CFG_LOCKERS == yes ]] && ! fu_pam_lockers_enabled; then
+2 -2
View File
@@ -124,8 +124,8 @@ fu_config_load() {
_fu_kv_lookup "$FU_CONFIG" Enabled no; CFG_ENABLED=no; fu_is_true "$FU_KV_VALUE" && CFG_ENABLED=yes
_fu_kv_lookup "$FU_CONFIG" LockScreen yes; CFG_LOCK=no; fu_is_true "$FU_KV_VALUE" && CFG_LOCK=yes
_fu_kv_lookup "$FU_CONFIG" Sudo no; CFG_SUDO=no; fu_is_true "$FU_KV_VALUE" && CFG_SUDO=yes
_fu_kv_lookup "$FU_CONFIG" Polkit no; CFG_POLKIT=no; fu_is_true "$FU_KV_VALUE" && CFG_POLKIT=yes
_fu_kv_lookup "$FU_CONFIG" Sudo yes; CFG_SUDO=no; fu_is_true "$FU_KV_VALUE" && CFG_SUDO=yes
_fu_kv_lookup "$FU_CONFIG" Polkit yes; CFG_POLKIT=no; fu_is_true "$FU_KV_VALUE" && CFG_POLKIT=yes
_fu_kv_lookup "$FU_CONFIG" LockScreens yes; CFG_LOCKERS=no; fu_is_true "$FU_KV_VALUE" && CFG_LOCKERS=yes
_fu_kv_lookup "$FU_SYSCONFIG" Liveness light; CFG_LIVENESS="$FU_KV_VALUE"
+2 -2
View File
@@ -306,8 +306,8 @@ FU_SETTINGS=(
"user|LockWallpaper|path||Wallpaper||LockScreenStyle=own|ownlock"
"user|LockBlur|bool|no|Blur the wallpaper||LockScreenStyle=own|ownlock"
"group|Password prompts"
"pam|sudo|bool|no|sudo in a terminal"
"pam|polkit-1|bool|no|Admin prompts"
"pam|sudo|bool|yes|sudo in a terminal"
"pam|polkit-1|bool|yes|Admin prompts"
"pam|lockscreens|bool|yes|Lock screens|||lockers"
"sys|SshSessions|bool|no|In SSH sessions"
"group|Recognition"
+6
View File
@@ -114,6 +114,12 @@ fu_pam_lockers_enabled() {
(( found ))
}
# fu_pam_available <service>
# Whether the service has a PAM file here at all.
fu_pam_available() {
[[ -f $(fu_pam_etc "$1") ]] || fu_pam_vendor "$1" > /dev/null
}
# fu_pam_enabled <service>
fu_pam_enabled() {
local file